-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy pathsysctl.conf
More file actions
47 lines (41 loc) · 1.44 KB
/
Copy pathsysctl.conf
File metadata and controls
47 lines (41 loc) · 1.44 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
net.core.somaxconn=65536
net.core.netdev_max_backlog=524288
net.ipv4.conf.default.rp_filter=1
net.ipv4.conf.all.rp_filter=1
#It is safe to enable syn cookies because there is no outside port
#connections that isn't already controlled by Tor or I2P processes.
#Potental attack vector in a I2P DDOS attack but there are systems
#built into I2P to prevent SYN flood attacks from causing major problems
net.ipv4.tcp_syncookies=1
net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rfc1337 = 1
net.ipv4.tcp_fin_timeout = 20
net.ipv4.tcp_keepalive_time = 240
net.ipv4.tcp_slow_start_after_idle = 0
net.ipv4.tcp_retries2 = 8
net.ipv4.tcp_tw_reuse = 1
net.ipv4.tcp_low_latency = 1
net.ipv4.ip_local_port_range = 10000 65000
fs.file-max = 8388608
#add BBR congestion control support
net.core.default_qdisc=fq
net.ipv4.tcp_congestion_control=bbr
#Hardening
dev.tty.ldisc_autoload = 0
fs.protected_fifos = 2
kernel.core_uses_pid = 1
kernel.kptr_restrict = 2
kernel.sysrq = 0
kernel.unprivileged_bpf_disabled =1
kernel.yama.ptrace_scope = 1
net.core.bpf_jit_harden = 2
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.log_martians = 1
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.default.accept_source_route = 0
net.ipv4.conf.default.log_martians = 1
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
#unsafe harden
#kernel.modules_disabled = 1